PRIVACY POLICY
This policy explains what we collect, why, where it goes and what you can do about it. It is written to comply with the Australian Privacy Act 1988 (APPs), the EU and UK GDPR, applicable US state privacy laws (including the CCPA/CPRA), Canada's PIPEDA and New Zealand's Privacy Act 2020. Short version: we collect what the game needs to run, we don't sell it, verification photos self-destruct in 24 hours, and you can delete everything in-app.
1. Who we are
Cache Of Credits is operated by Twisted Lunacy (ABN 21 979 134 918), Australia ("we", "us"). Contact: admin@cacheofcredits.com. For EU/UK data-protection queries, the same address reaches the privacy officer.
2. What we collect and why
- Account data — email address, hunter display name, password (stored as a cryptographic hash, never in readable form). Needed to run your account.
- Location data — GPS position while the app is in use, to run hunts: geofence detection (50m cache radius), anti-cheat checks and hunt features. We do not collect location in the background and we do not build movement profiles.
- Verification photos — when you submit photo proof of a find, the photo and its embedded metadata (including GPS coordinates and capture time) are analysed server-side to confirm the find. Photos are automatically and permanently deleted within 24 hours.
- Gameplay data — Cache Credits balance, hunt history, streaks, leaderboard entries, referral activity.
- Purchase data — purchases are processed by Apple, Google and RevenueCat. We receive purchase confirmations and entitlements; we never see or store your card number.
- Device and diagnostics — crash reports (Sentry, Crashlytics) and aggregated analytics events with hashed identifiers, to keep the app working. No advertising identifiers are used for tracking you across other companies' apps.
- Age band — your date of birth is checked on-device at the age gate to confirm you are 18+. It is not transmitted to our servers.
3. What we don't do
- We do not sell your personal information, and have not in the preceding 12 months (CCPA disclosure).
- We do not share your location with advertisers or data brokers.
- We do not use your verification photos for anything except verifying that find.
- We do not knowingly collect data from anyone under 18 — the game is age-gated at signup.
4. Legal bases (GDPR / UK GDPR)
Where the GDPR applies: account and gameplay processing is necessary to perform our contract with you (providing the game); location processing during hunts is contract performance and you control it through device permissions; anti-cheat and security processing is our legitimate interest in a fair game; diagnostics are legitimate interest with minimised data; anything else is consent, requested before collection and withdrawable in-app.
5. Where your data goes
Our infrastructure runs on Google Firebase (data hosted in the United States) and error reporting on Sentry (US). Under APP 8 and GDPR Chapter V, cross-border transfers rely on the providers' standard contractual clauses and equivalent safeguards. Purchase processing occurs with Apple, Google and RevenueCat under their own policies.
6. How long we keep it
- Verification photos: 24 hours maximum, enforced by an automated purge.
- Account and gameplay data: while your account exists.
- After account deletion: removed from production immediately; residual copies clear from backups within 35 days.
- Purchase records: as required by tax and consumer law (up to 7 years, Australia).
7. Your rights
Wherever you are, you can: access your data (in-app export, GDPR Art. 15 / APP 12 / CCPA right to know), correct it (APP 13 / GDPR Art. 16), delete it (in-app: Profile → Delete Account — GDPR Art. 17 erasure, CCPA deletion; the cascade removes your profile, hunt history, photos, and leaderboard entries), export it in machine-readable form (GDPR Art. 20), and complain to a regulator — the OAIC (Australia), your EU supervisory authority, the UK ICO, or your state Attorney-General (US). We will never discriminate against you for exercising any right.
8. Security
Data in transit is encrypted (TLS). Passwords are hashed. Photo verification runs entirely server-side. Access to production data is restricted and logged. No system is perfectly secure; if a breach occurs that is likely to result in serious harm, we will notify affected users and the OAIC within 30 days, and where GDPR applies, the supervisory authority within 72 hours.
9. Children
Cache Of Credits is for adults 18+. The age gate blocks under-18 signups before any account exists and before any purchase is possible. If we learn an account belongs to a minor, we delete it.
10. Changes
Material changes will be announced in-app and on this page before they take effect, with the version and date updated above.